I am committed to complying with the terms of the General Data Protection Regulation (GDPR) and to the responsible and secure use of your data. I have a legitimate interest in processing personal data to provide counselling services and may change this policy from time-to-time in line with legislation. The purpose of this statement is to let you know what personal information I collect and hold, why I collect this data, how long it is stored, and your rights to your data. I am registered with the Information Commissioner’s Office (ICO), reference ZB228806. By, having therapy with me, you are accepting and consenting to practices described in this policy.
Information I collect
My website uses Google Analytics, a marketing tool that looks at traffic coming to the site and how it got there. It also records your IP address which can identify you. However, Google does not give me access to this IP address.
I collect personal information from you when you enquire about my therapy services and set up an initial appointment. This information includes contact details, your availability and other relevant personal information. I also keep records such as client hours, to run and maintain my business and brief notes on our sessions. Client notes contain no identifiable information and initials only.
When you enquire about therapy, I ask for contact details and relevant personal information from you. This is needed to answer your enquiries and to keep you informed. If you contact me via phone, email or text no data will be stored on my website or passed to any third party. On the ‘Contact’ page, you are invited to either email or text me. No details are kept on the website.
How I use and store information
Your telephone number will be stored on my mobile phone under your initials or your first name only until you end therapy. At this point, it will be deleted unless you wish me to keep the number in case you choose to return for any future sessions. If I change my telephone then your details will be deleted from the old phone.
I keep brief notes of of our therapy sessions. These are stored in a password-protected file and laptop online and destroyed 7 years after you end therapy unless agreed otherwise.
Your data will be used only to provide you with my services and to give you information relating to those services. I will not share your details with any other person or organisation without your knowledge and permission unless I am required to by law. A breach of confidentiality is when a person shares information with another in circumstances where it is reasonable to expect that the information will be kept confidential.
Security
My website has an SSL certificate which shows that the data connection to an internet page is secured with a Secure Sockets Layer (SSL). This ensures that the transferred data cannot be read or modified by third parties.
I will take all reasonable precautions to prevent the loss, misuse, or alteration of information you give me.
Communications concerning this service might be sent by email. I use an encrypted email provider to store emails I send and receive. However, for ease of use and compatibility, communications will not be end-to-end encrypted unless you require it. Email, unless encrypted, is not a fully secure means of communication. Whilst I endeavour to keep our systems and communications protected against viruses and other harmful effects, I cannot bear responsibility for all communications being virus-free. Communications might be done by text message. Both my laptop and mobile phone are password protected.
In the event of my death
In the event of my death, the contact details of all clients will be passed to my Clinical Executor to ensure all are contacted and advised. All my clinical notes will be destroyed by my Clinical Executor.
Your rights to your personal data
If you would like to see the information I hold about you or would like to correct, update, or delete any records, please email me at hello@guidedbysarah.co.uk.
Concerns or complaints
If you have any concerns about my use of your data, please email me at hello@guidedbysarah.co.uk and I will do my utmost to resolve any concerns you have. I would welcome any suggestions for improving my data protection procedures. I will acknowledge any complaint within 30 days, keep you informed of progress, and explain the outcome. If l am uncertain of the identity of the person making the complaint, I may request additional identification information (such as phoning you on the number have on file or checking with you your date of birth). If you are complaining on behalf of someone else, I will be obliged to check you have the authority to act on their behalf either confirmation of power of attorney or a signed letter of authority from the person you are writing on behalf of).
If you want to make a formal complaint about the way I have processed your personal information you can contact the ICO which is the statutory body that oversees data protection law in the UK. For more information go to ico.org.uk/make-a-complaint.